Teams facing a first audit, a failed one, or a scope change.
Three situations bring organizations to us. A customer or investor has asked for a SOC 2 Type 2 report and there is no control environment to point at yet. A first-year SOX company needs IT general controls designed, documented, and tested before the external auditor arrives. Or an ISO/IEC 27001 certification is up for surveillance and the internal audit function has fallen behind. In each case the underlying need is the same: controls that are actually operating, and evidence that proves it without a scramble.
What you getThe audit file, built before the audit.
- Readiness assessment — a control-by-control review against the SOC 2 Trust Services Criteria, the COSO-aligned ITGC domains (access, change, operations, program development), or ISO/IEC 27001:2022 Annex A, with each control rated designed / operating / not in place.
- Control design and narratives — right-sized controls with owners, frequency, and precision defined; process narratives and risk-control matrices auditors recognize on sight.
- Test of design and operating effectiveness — sample-based testing using the same methodology the external auditor will apply, so exceptions surface with you first.
- Evidence library and PBC management — a request list mapped to controls, an evidence repository organized by period, and a coordination cadence for the audit itself.
- Remediation and finding closure — root-cause analysis for every exception, a corrective action plan, and re-testing to confirm closure.
We audit you before the auditor does.
Scope and criteria
Which systems, which criteria, which period. Getting the system description and boundary right avoids the most common SOC 2 qualification: controls described that were never tested.
Design, then evidence
Every control gets an owner, a frequency, and a named artifact. If the artifact cannot be produced on demand, the control is redesigned until it can.
Test and remediate
We pull samples, test, and document exceptions the way the auditor will. Findings become a board-ready remediation roadmap with dates and owners.
Common questions.
SOC 2 Type 1 or Type 2 — which should we pursue first?
Do you perform the audit itself?
Can you work inside our GRC platform?
Walk in prepared. Walk out with findings that hold up.
Tell us which audit is coming and when. We will tell you what it takes to be ready.